Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Browser connecten nicht mehr richtig (https://www.trojaner-board.de/14174-browser-connecten-mehr-richtig.html)

Tobi!!!!!!! 20.02.2005 14:34

Browser connecten nicht mehr richtig
 
Hallo!
Hab seit ein paar Tagen ein Problem mit meinem Internet. Benutze Firefox, aber daran scheint es nciht zu liegen,weils beim IE das selbe ist:

Der Browser connectet total langsam, das heisst er zeigt immer an "nachschlagen von....." und "verbunden mit...."
Dann passiert ganz lange (5-10 sec) nichts und dann öffnet nicht meistens die seite erst. Manchmal kommt es aber auch vor, dass ne Fehlermeldung kommt und die Anwendung(browser) beendet wird.

Kann mir vielleicht jemand helfen. Hab mal ne log file erstellt, war allerdings glaube ich mit ner alten version, macht aber nichts oder??


Logfile of HijackThis v1.98.2
Scan saved at 14:28:22, on 20.02.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
T:\Nero\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
T:\Nero\SAVScan.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
C:\Programme\Parallel Tasking\ptask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Internet\ICQLite\ICQLite.exe
D:\Internet\Firefox\firefox.exe
I:\Mp3´s\Winamp3\Studio.exe
D:\Internet\Installer\hijackthis\HijackThis.exe
C:\Programme\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://allwebseek.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://allwebseek.com
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - T:\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - T:\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - T:\Nero\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - T:\Nero\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Parallel Tasking] C:\Programme\Parallel Tasking\ptask.exe
O4 - HKLM\..\Run: [5WtJTdvQ] C:\WINDOWS\ebvmg.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\Internet\ICQLite\ICQLite.exe -trayboot
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Internet\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Internet\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe


Vielen dank

tobi

chaosman 20.02.2005 14:42

@Tobi!!!!!!!
der hier ist im system
http://www.sophos.de/virusinfo/analy...dloaderfy.html

wechsle in den abgesicherten modus und fixe mit HJT
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://allwebseek.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://allwebseek.com
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [Parallel Tasking] C:\Programme\Parallel Tasking\ptask.exe
lösche danach manuell
C:\Programme\Parallel Tasking\ptask.exe
neu booten, neues logfile posten
chaosman

Tobi!!!!!!! 20.02.2005 15:09

Hallo!
Ersteinmal danke für die super schnelle antwort!!!!!!

Also: Hab gemacht was Du geschrieben hast, aber als ich hier die seite aufgerufen haben, war wieder dasselbe Problem da. Naja hier ist erstmal das neue Logfile:

Logfile of HijackThis v1.98.2
Scan saved at 15:06:47, on 20.02.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
T:\Nero\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
T:\Nero\SAVScan.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programme\Messenger\msmsgs.exe
D:\Internet\Installer\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - T:\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - T:\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - T:\Nero\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - T:\Nero\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [5WtJTdvQ] C:\WINDOWS\ebvmg.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Internet\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Internet\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe


tobi

chaosman 20.02.2005 15:29

@Tobi!!!!!!!
lade escan
download
anleitung
überprüfe Deinen Rechner zunächst mit dem eScan: lade den eScan runter, erstelle dafür einen Ordner (=Verzeichnis) c:\bases, update den eScan online und führe ihn offline im abgesicherten Modus aus. Beachte, dass der eScan ab Version 4.5.1 gefundene Malware nicht löscht. Das wird von Hand auf Anweisung durch uns gemacht.

Teile uns dann das Ergebnis des eScan mit: welche Viren wurden auf Deinem Rechner gefunden: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." (Zitat Cidre)

chaosman

Tobi!!!!!!! 20.02.2005 21:34

hallo!

Also hab alles so gemacht wie beschrieben. das ist dabei rausgekommen. (kommt mir nen bisschen viel vor, die Zahl der Treffer, oder ist das normal??)


Sun Feb 20 17:44:08 2005 => File C:\WINDOWS\system32\olexp.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.

Sun Feb 20 17:45:16 2005 => File C:\DOKUME~1\Tobias\LOKALE~1\Temp\ping41.exe infected by "Trojan-Downloader.Win32.Small.agn" Virus. Action Taken: No Action Taken.

Sun Feb 20 17:47:55 2005 => File C:\DOKUME~1\Tobias\LOKALE~1\TEMPOR~1\Content.IE5\WRWGUAZ5\webrebates_europe[1].exe infected by "not-a-virus:AdWare.WebRebates.g" Virus. Action Taken: No Action Taken.

Sun Feb 20 17:48:18 2005 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.


Sun Feb 20 17:51:03 2005 => File C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Temp\ping41.exe infected by "Trojan-Downloader.Win32.Small.agn" Virus. Action Taken: No Action Taken.

Sun Feb 20 17:52:51 2005 => File C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WRWGUAZ5\webrebates_europe[1].exe infected by "not-a-virus:AdWare.WebRebates.g" Virus. Action Taken: No Action Taken.

Sun Feb 20 17:59:58 2005 => File C:\System Volume Information\_restore{D36C0CE7-8515-4EB9-B6CE-B1D4DF9396CA}\RP71\A0007089.exe infected by "Trojan-Downloader.Win32.Small.ajs" Virus. Action Taken: No Action Taken.

Sun Feb 20 18:00:13 2005 => File C:\System Volume Information\_restore{D36C0CE7-8515-4EB9-B6CE-B1D4DF9396CA}\RP74\A0007184.exe infected by "Trojan-Downloader.Win32.Agent.iw" Virus. Action Taken: No Action Taken.


Sun Feb 20 18:00:50 2005 => File C:\System Volume Information\_restore{D36C0CE7-8515-4EB9-B6CE-B1D4DF9396CA}\RP82\A0007424.exe infected by "Trojan-Downloader.Win32.Small.agn" Virus. Action Taken: No Action Taken.

Sun Feb 20 18:10:48 2005 => File C:\WINDOWS\system32\olexp.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => File T:\Nero\Quarantine\02C514E7 infected by "Trojan-Downloader.Win32.INService.i" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => Scanning File T:\Nero\Quarantine\0E5550E6
Sun Feb 20 20:01:19 2005 => File T:\Nero\Quarantine\0E5550E6 infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => Scanning File T:\Nero\Quarantine\0F345C15
Sun Feb 20 20:01:19 2005 => File T:\Nero\Quarantine\0F345C15 infected by "Trojan-Downloader.Win32.IstBar.gj" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => Scanning File T:\Nero\Quarantine\150B73C9.exe
Sun Feb 20 20:01:19 2005 => File T:\Nero\Quarantine\150B73C9.exe infected by "Trojan-Downloader.Win32.Agent.iw" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => Scanning File T:\Nero\Quarantine\18265D83
Sun Feb 20 20:01:19 2005 => File T:\Nero\Quarantine\18265D83 infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => Scanning File T:\Nero\Quarantine\19E50CE4
Sun Feb 20 20:01:19 2005 => File T:\Nero\Quarantine\19E50CE4 infected by "Trojan-Downloader.Win32.Dyfuca.dk" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:19 2005 => Scanning File T:\Nero\Quarantine\1C3B776D
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1C3B776D infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1E200A34.exe
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1E200A34.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1EDA6367.exe
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1EDA6367.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1F4B1C29
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1F4B1C29 infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1F527022
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1F527022 infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1F551A1E
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1F551A1E infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1F58441B
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1F58441B infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\1FA1648C.exe
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\1FA1648C.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\206865B1.exe
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\206865B1.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\208D5CCD
Sun Feb 20 20:01:20 2005 => File T:\Nero\Quarantine\208D5CCD infected by "Trojan-Downloader.Win32.INService.i" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:20 2005 => Scanning File T:\Nero\Quarantine\209006C9
Sun Feb 20 20:01:21 2005 => File T:\Nero\Quarantine\209006C9 infected by "Trojan-Downloader.Win32.INService.i" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\209430C6
Sun Feb 20 20:01:21 2005 => File T:\Nero\Quarantine\209430C6 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\20975AC2
Sun Feb 20 20:01:21 2005 => File T:\Nero\Quarantine\20975AC2 infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\209A04BE
Sun Feb 20 20:01:21 2005 => File T:\Nero\Quarantine\209A04BE infected by "Trojan-Downloader.Win32.Dyfuca.dk" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\209D2EBB
Sun Feb 20 20:01:21 2005 => File T:\Nero\Quarantine\209D2EBB infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\20A158B7
Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\20A402B4
Sun Feb 20 20:01:21 2005 => File T:\Nero\Quarantine\20A402B4 infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:21 2005 => Scanning File T:\Nero\Quarantine\20A72CB0
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\20A72CB0 infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\20AA56AD
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\20AA56AD infected by "Trojan-Downloader.Win32.Dyfuca.dc" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\213310D2.exe
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\213310D2.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\21765AA8
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\21765AA8 infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\21FA11F7.exe
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\21FA11F7.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\22C86714.exe
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\22C86714.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\238B3E3D.exe
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\238B3E3D.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\2494071A.exe
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\2494071A.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\257648E3
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\257648E3 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\257D34B6
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\257D34B6 infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\258308AF
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\258308AF infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\25862A10.exe
Sun Feb 20 20:01:22 2005 => File T:\Nero\Quarantine\25862A10.exe infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:22 2005 => Scanning File T:\Nero\Quarantine\258732AB
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\258732AB infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\258A5CA8
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\258A5CA8 infected by "Trojan-Downloader.Win32.IstBar.gn" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\2667017B
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\2667017B infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\296D59C4
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\296D59C4 infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\310604E2
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\310604E2 infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\315730EF
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\315730EF infected by "Trojan-Downloader.Win32.Agent.iw" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\315A5AEB
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\315A5AEB infected by "Trojan-Downloader.Win32.Agent.iw" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\3B4701AF
Sun Feb 20 20:01:23 2005 => File T:\Nero\Quarantine\3B4701AF infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:23 2005 => Scanning File T:\Nero\Quarantine\40B4551F
Sun Feb 20 20:01:24 2005 => File T:\Nero\Quarantine\40B4551F infected by "Trojan-Downloader.Win32.TSUpdate.i" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:24 2005 => Scanning File T:\Nero\Quarantine\47913ED6
Sun Feb 20 20:01:24 2005 => File T:\Nero\Quarantine\47913ED6 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:24 2005 => Scanning File T:\Nero\Quarantine\488D72E6
Sun Feb 20 20:01:24 2005 => File T:\Nero\Quarantine\488D72E6 infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:24 2005 => Scanning File T:\Nero\Quarantine\4EB110D2
Sun Feb 20 20:01:24 2005 => File T:\Nero\Quarantine\4EB110D2 infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:24 2005 => Scanning File T:\Nero\Quarantine\4FE869AC
Sun Feb 20 20:01:24 2005 => File T:\Nero\Quarantine\4FE869AC infected by "Trojan-Downloader.Win32.IstBar.gt" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:24 2005 => Scanning File T:\Nero\Quarantine\538E5E47
Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\541D2EE5
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\541D2EE5 infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\55D262CD
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\55D262CD infected by "Trojan-Downloader.Win32.INService.i" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\5FAE6AE4
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\5FAE6AE4 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\675C13E5
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\675C13E5 infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\679A0AA7.exe
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\679A0AA7.exe infected by "Trojan-Downloader.Win32.Small.ajs" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\6B3E26E2
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\6B3E26E2 infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\6FDC4E2D
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\6FDC4E2D infected by "Trojan-Downloader.Win32.IstBar.er" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\76FC2028
Sun Feb 20 20:01:25 2005 => File T:\Nero\Quarantine\76FC2028 infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:25 2005 => Scanning File T:\Nero\Quarantine\77C119BA
Sun Feb 20 20:01:26 2005 => File T:\Nero\Quarantine\77C119BA infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:26 2005 => Scanning File T:\Nero\Quarantine\786E2D26
Sun Feb 20 20:01:26 2005 => File T:\Nero\Quarantine\786E2D26 infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:26 2005 => Scanning File T:\Nero\Quarantine\7875011F
Sun Feb 20 20:01:26 2005 => File T:\Nero\Quarantine\7875011F infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:26 2005 => Scanning File T:\Nero\Quarantine\78782B1B
Sun Feb 20 20:01:26 2005 => File T:\Nero\Quarantine\78782B1B infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:26 2005 => Scanning File T:\Nero\Quarantine\787B5517
Sun Feb 20 20:01:26 2005 => File T:\Nero\Quarantine\787B5517 infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken.

Sun Feb 20 20:01:26 2005 => Scanning File T:\Nero\Quarantine\7E1C7224
Sun Feb 20 20:01:26 2005 => File T:\Nero\Quarantine\7E1C7224 infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus. Action Taken: No Action Taken.

Tobi

chaosman 21.02.2005 20:29

@Tobi!!!!!!!

ich würde hier auf sicher gehen und neuaufsetzen(formatC)
Win32.Bagz.h die meiste aus dieser familie haben backdoor eigenschaften.
der damage potenzial ist sehr hoch.
http://securityresponse.symantec.com...bagz.h@mm.html
http://de.trendmicro-europe.com/ente...me=WORM_BAGZ.I
hier eine anleitung zum neuaufsetzen
http://www.trojaner-board.de/showpos...28&postcount=2


sry
chaosman


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:05 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129